The EU AI Act for deployers: what you actually have to do
Updated July 8, 2026
If you use AI rather than build and sell it, the Act calls you a deployer, and you have real duties, just lighter ones than a provider. Two of them are already in force, transparency lands in August 2026, and, under the Digital Omnibus, the big high-risk duties are now deferred to December 2027. Here is what that actually means, in plain terms.
This is a readiness explainer, not legal advice. For your specific position, get advice, or check where you stand in ten minutes.
Are you a deployer?
A deployer is an organisation that uses an AI system under its own authority. Most businesses are deployers: you use an AI tool for hiring, support, analysis or content, but you did not develop it. A provider is the one who builds the system or puts it on the market under their own name.
The line matters because the obligations differ. And you can cross it without meaning to: rebrand someone else’s AI as your own, or significantly modify it, and you may pick up provider obligations too (Article 25). That is worth knowing before it surprises you.
What you already have to do
Two duties are live now, not in 2026:
- AI literacy (Article 4). Since February 2025, you must ensure the people who use or are affected by your AI understand it well enough to use it responsibly. It applies whatever the risk level. It is the easiest duty to start on and the one most often forgotten. We cover it in full in AI literacy: the Article 4 duty in practice.
- No prohibited practices (Article 5). Some uses are banned outright, including social scoring and emotion recognition in the workplace. Using one is the fastest route to the heaviest penalties. You need to know none of the AI you use, or that a vendor quietly adds, falls into this bucket.
What lands next: transparency, then high-risk
Two dates matter here, and the Digital Omnibus has pulled them apart.
From 2 August 2026, transparency (Article 50). Tell people when they are interacting with AI, and label AI-generated or deepfake content you publish. This date was not deferred.
From 2 December 2027, the core high-risk deployer duties. If you deploy high-risk AI (think hiring, credit, education, essential services), these now apply from here rather than August 2026:
- Use it responsibly (Article 26): follow the provider’s instructions, assign competent human oversight, monitor how it performs, and keep logs.
- Assess the impact on people (Article 27): where required, run a Fundamental Rights Impact Assessment before first use, and connect it to your data-protection assessment.
One caveat worth stating plainly: the Digital Omnibus is agreed but not yet formally adopted. Until it is published in the Official Journal (expected around August 2026), the December 2027 deferral is settled policy rather than settled law. Plan around it; watch for the final text.
Does it reach UK and non-EU companies?
Yes, often. The Act applies extraterritorially. If the outputs of the AI you use affect people in the EU, or you operate in the EU market, you can be in scope even with no EU office. “We’re not in the EU” is not the shield people assume it is.
What it costs to get this wrong
Penalties are tiered and reach up to €35M or 7% of global annual turnover for the most serious breaches. But the quieter cost arrives sooner: enterprise buyers increasingly ask vendors to prove their AI is governed. No evidence, no shortlist. The Act is becoming a procurement gate, not just a legal risk.
Where to start
You cannot manage what you have not mapped. The first moves are unglamorous and high-value: list the AI you use, classify each by risk, confirm none is prohibited, and start the literacy work. From there, the high-risk duties become a checklist rather than a scramble.
If you want an honest read on where you stand today, the free EU AI Act readiness assessment takes about ten minutes and gives you a score and your biggest gaps, no email required to see them. When you are ready to act on it, talk to us about putting real governance in place before the deadline does it for you.
For the full picture, see the EU AI Act guide.
Frequently asked questions
Does the EU AI Act apply to my company if we only use AI tools?
Yes. Using AI under your own authority makes you a deployer, and deployers have obligations under the Act. They are lighter than a provider's, but they are real, and some are already in force.
Does the EU AI Act apply to UK and other non-EU companies?
It can. The Act applies extraterritorially: if the outputs of the AI you use affect people in the EU, or you put AI on the EU market, you can be in scope regardless of where you are based.
When do the main deployer obligations start?
AI literacy (Article 4) and the ban on prohibited practices (Article 5) are already in force. The transparency duties (Article 50) apply from 2 August 2026. The core high-risk deployer duties (Articles 26 and 27) were originally set for 2 August 2026 too, but under the EU's Digital Omnibus (agreed in 2026, pending formal adoption) they are deferred to 2 December 2027.
What are the penalties?
They are tiered by the type of breach and reach up to €35M or 7% of global annual turnover for the most serious, such as using a prohibited system.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert